CVE Database
/

CVE-2022-43504

Back to search

CVE-2022-43504

Published: Dec 5, 2022

Modified: Apr 24, 2025

PUBLISHED

Description

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

VendorProductVersions

WordPress.org

WordPress

affected
versions prior to 6.0.3

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now